
TokenTacticsV2
A fork of the great TokenTactics with support for CAE and token endpoint v2

A fork of the great TokenTactics with support for CAE and token endpoint v2

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

ThePhish: an automated phishing email analysis tool

Node.js command-and-control server with FUD payload generation, encrypted communication, session management, and modules for data exfiltration and…

Cross Site Scripting on sanitization-management-system

A toolkit to attack Office365